Fun

News Feed - 2023-09-11 10:09:19

Brayden Lindrea7 hours agoLido assures LDO, stETH tokens remain safe despite flaw in token contractThe “fake deposit” attack enables bad actors to execute a transfer where the requested value is larger than what the user actually owns.2581 Total views21 Total sharesListen to article 0:00NewsJoin us on social networksEthereum staking protocol Lido Finance has assured both Lido DAO (LDO) and staked-Ether (stETH) tokens remain safe despite hackers allegedly exploiting a known security flaw in LDO’s token contract.


Lido didn’t confirm any exploits, but acknowledged the security flaw was known and reassured LDO and stETH funds remain safe in response to a Sept. 10 post by blockchain security firm SlowMist.


SlowMist said LDO’s flawed token contract allows bad actors to facilitate “fake deposit” attacks on exchanges because LDO’s token contract enables users to execute transactions even where they don’t have sufficient funds. This code deviates from the Ethereum Request for Comment 20 (ERC-20) token standard, according to SlowMist.


However, Lido Finance argued the flaw is built into all ERC-20 tokens — not just Lido’s LDO token:This behaviour is expected and conforms to the ERC20 token standard (see tweet below). Both LDO and stETH (and Lido governance) remain safe.

Lido token integration guides will be updated with LDO specifics to make this more visible shortly.— Lido (@LidoFinance) September 10, 2023


SlowMist said the “fake deposit” attacks came from LDO’s token contract executing transfers where the value is larger than what the user actually owns, triggering a false return as opposed to reverting the transaction. While the firm said Lido’s token contract has recently been exploited via this attack, no on-chain evidence was provided.


Cointelegraph reached out to SlowMist for comment but did not receive an immediate response.


Meanwhile, on-chain analyst “Hercules” explained on Sept. 10 that the security flaw may not be picked up by cryptocurrency exchanges.


SlowMist recommends LDO holders to also check the return values of the token contract transfers in addition to the success or failure of a transaction.


The blockchain security firm concluded that token contract implementations and behaviors vary by project and to conduct comprehensive testing before integrating any new tokens.


Related:Ethereum staking services agree to 22% limit of all validators


However, Lido highlighted in the official Ethereum Improvement Proposal document — co-authored by Vitalik Buterin in November 2015 — that both the “transfer” and “transferFrom” functions must return the transfer status and are only recommended to revert a transaction in exceptional cases.ERC20 token standard: https://t.co/YlrS1ZN6Fd

1) Both transfer and transferFrom are required to return transfer status and are only recommended to revert a tx in exceptional cases.

2) The standard says that a caller is obliged to check the return status (see 'Token methods'). pic.twitter.com/6KTcIyxo2F— Lido (@LidoFinance) September 10, 2023


To resolve the security flaw, Lido confirmed that the LDO token integration guides will soon be updated.


Collect this article as an NFTto preserve this moment in history and show your support for independent journalism in the crypto space.


Magazine:DeFi Dad, Hall of Flame: Ethereum is ‘woefully undervalued’ but growing more powerful# Altcoin# Security# Ethereum# Hackers# DAO# ERC-20# DeFi# Staking# Lido DAOAdd reactionAdd reactionRead moreHow to actually spend your Bitcoin, ExplainedCrypto VC: Risk and investment strategies with Shima CapitalHuman vs. AI: Who is better at crypto investing?

News Feed

5 things you didn't know about Bitcoin halvings and BTC price
Yashu Gola12 hours ago5 things you didn"t know about Bitcoin halvings and BTC priceAs the market approaches Bitcoin"s fourth halving on April 19, let"s explore five intriguing facts about this phenomenon that may surpris
Lebanese Currency Collapse: Failed Policies Led to Economic Meltdown
Lebanese Currency Collapse: Failed Policies Led to Economic MeltdownLebanon is facing an unprecedented economic crisis and the local currency has already lost about 60% of its value
Unity Gaming Engine Launches Blockchain and Web3 Integration Options
Unity Gaming Engine Launches Blockchain and Web3 Integration Options Unity, a gaming engine development company, has announced the introduction of several blockchain-based integrat
‘Ethereum Killers’ Managed to ‘Kill’ Themselves in 2022 Rather Than Beat the Smart Contract Economy’s Heavyweight Champ
‘Ethereum Killers’ Managed to ‘Kill’ Themselves in 2022 Rather Than Beat the Smart Contract Economy’s Heavyweight Champ At the end of 2021, a myriad of people thought a h
Dow Futures Pump 100 points, but Ex-White House Insider Warns of Recession
Dow futures jump 100 points despite warning from former White House advisor and Treasury Secretary. Source: Shutterstock The US stock market looks set t
Ethereum Weekly Volume Hits $60 Billion As ETH Aims For Yearly Highs
Este artículo también está disponible en español. Ethereum has staged an impressive 35% rally since last Tuesday, marking a bullish breakout as it tests crucial supply le
Bitfinex database breach 'seems fake,' says CTO
Ciaran Lyons3 hours agoBitfinex database breach "seems fake," says CTOBitfinex CTO Paolo Ardoino explained that if the hacking group was telling the truth, they would have asked for a ransom, but he "couldn"t find a
Quidax Becomes the First African Crypto Exchange to be Listed on CoinMarketCap
Quidax Becomes the First African Crypto Exchange to be Listed on CoinMarketCap press release PRESS RELEASE. Last week Africa founded cryptocurrency exchange, Quidax, announced that
Helen Partz9 hours agoBitcoin ETF to trigger massive demand from institutions, EY saysBitcoin is facing a lot of pent-up demand from institutions amid investors closely monitoring spot Bitcoin ETF news, Ernst & Young
Analysts Predict US Presidential Election Outcome Could Collapse Dollar, Boost Bitcoin and Gold
Analysts Predict US Presidential Election Outcome Could Collapse Dollar, Boost Bitcoin and GoldAnalysts have predicted a bearish outlook for the U.S. dollar as the country’s 2
Tether mints 1.3B USDT since market bottom — Can it push Bitcoin above $65K?
Zoltan Vardai11 hours agoTether mints 1.3B USDT since market bottom — Can it push Bitcoin above $65K?The newly minted stablecoins could help push Bitcoin’s price above the $65,000 resistance, which is the short-term
Last Crash Before The Surge: Why Bitcoin Is Set To Drop Below $107,000
Reason to trust Strict editorial policy that focuses on accuracy, relevance, and impartiality Created by industry experts and meticulously reviewed The highest standards in reporting and pu